1//===-- sanitizer_coverage_libcdep_new.cpp --------------------------------===//
2//
3// Part of the LLVM Project, under the Apache License v2.0 with LLVM Exceptions.
4// See https://llvm.org/LICENSE.txt for license information.
5// SPDX-License-Identifier: Apache-2.0 WITH LLVM-exception
6//
7//===----------------------------------------------------------------------===//
8// Sanitizer Coverage Controller for Trace PC Guard.
9
10#include "sanitizer_platform.h"
11
12#if !SANITIZER_FUCHSIA
13# include "sancov_flags.h"
14# include "sanitizer_allocator_internal.h"
15# include "sanitizer_atomic.h"
16# include "sanitizer_common.h"
17# include "sanitizer_common/sanitizer_stacktrace.h"
18# include "sanitizer_file.h"
19# include "sanitizer_interface_internal.h"
20
21using namespace __sanitizer;
22
23using AddressRange = LoadedModule::AddressRange;
24
25namespace __sancov {
26namespace {
27
28static const u64 Magic64 = 0xC0BFFFFFFFFFFF64ULL;
29static const u64 Magic32 = 0xC0BFFFFFFFFFFF32ULL;
30static const u64 Magic = SANITIZER_WORDSIZE == 64 ? Magic64 : Magic32;
31
32static fd_t OpenFile(const char* path) {
33 error_t err;
34 fd_t fd = OpenFile(filename: path, mode: WrOnly, errno_p: &err);
35 if (fd == kInvalidFd)
36 Report(format: "SanitizerCoverage: failed to open %s for writing (reason: %d)\n",
37 path, err);
38 return fd;
39}
40
41static void GetCoverageFilename(char* path, const char* name,
42 const char* extension) {
43 CHECK(name);
44 internal_snprintf(buffer: path, length: kMaxPathLength, format: "%s/%s.%zd.%s",
45 common_flags()->coverage_dir, name, internal_getpid(),
46 extension);
47}
48
49static void WriteModuleCoverage(char* file_path, const char* module_name,
50 const uptr* pcs, uptr len) {
51 GetCoverageFilename(path: file_path, name: StripModuleName(module: module_name), extension: "sancov");
52 fd_t fd = OpenFile(path: file_path);
53 WriteToFile(fd, buff: &Magic, buff_size: sizeof(Magic));
54 WriteToFile(fd, buff: pcs, buff_size: len * sizeof(*pcs));
55 CloseFile(fd);
56 Printf(format: "SanitizerCoverage: %s: %zd PCs written\n", file_path, len);
57}
58
59static void SanitizerDumpCoverage(const uptr* unsorted_pcs, uptr len) {
60 if (!len) return;
61
62 char* file_path = static_cast<char*>(InternalAlloc(size: kMaxPathLength));
63 char* module_name = static_cast<char*>(InternalAlloc(size: kMaxPathLength));
64 uptr* pcs = static_cast<uptr*>(InternalAlloc(size: len * sizeof(uptr)));
65
66 internal_memcpy(dest: pcs, src: unsorted_pcs, n: len * sizeof(uptr));
67 Sort(v: pcs, size: len);
68
69 bool module_found = false;
70 uptr last_base = 0;
71 uptr module_start_idx = 0;
72
73 for (uptr i = 0; i < len; ++i) {
74 const uptr pc = pcs[i];
75 if (!pc) continue;
76
77 if (!GetModuleAndOffsetForPc(pc, module_name: nullptr, module_name_len: 0, pc_offset: &pcs[i])) {
78 Printf(format: "ERROR: unknown pc %p (may happen if dlclose is used)\n",
79 (void*)pc);
80 continue;
81 }
82 uptr module_base = pc - pcs[i];
83
84 if (module_base != last_base || !module_found) {
85 if (module_found) {
86 WriteModuleCoverage(file_path, module_name, pcs: &pcs[module_start_idx],
87 len: i - module_start_idx);
88 }
89
90 last_base = module_base;
91 module_start_idx = i;
92 module_found = true;
93 GetModuleAndOffsetForPc(pc, module_name, module_name_len: kMaxPathLength, pc_offset: &pcs[i]);
94 }
95 }
96
97 if (module_found) {
98 WriteModuleCoverage(file_path, module_name, pcs: &pcs[module_start_idx],
99 len: len - module_start_idx);
100 }
101
102 InternalFree(p: file_path);
103 InternalFree(p: module_name);
104 InternalFree(p: pcs);
105}
106
107// Collects trace-pc guard coverage.
108// This class relies on zero-initialization.
109class TracePcGuardController {
110 public:
111 void Initialize() {
112 CHECK(!initialized);
113
114 initialized = true;
115 InitializeSancovFlags();
116
117 pc_vector.Initialize(initial_capacity: 0);
118 }
119
120 void InitTracePcGuard(u32* start, u32* end) {
121 if (!initialized) Initialize();
122 CHECK(!*start);
123 CHECK_NE(start, end);
124
125 u32 i = pc_vector.size();
126 for (u32* p = start; p < end; p++) *p = ++i;
127 pc_vector.resize(new_size: i);
128 }
129
130 void TracePcGuard(u32* guard, uptr pc) {
131 u32 idx = *guard;
132 if (!idx) return;
133 // we start indices from 1.
134 atomic_uintptr_t* pc_ptr =
135 reinterpret_cast<atomic_uintptr_t*>(&pc_vector[idx - 1]);
136 if (atomic_load(a: pc_ptr, mo: memory_order_relaxed) == 0)
137 atomic_store(a: pc_ptr, v: pc, mo: memory_order_relaxed);
138 }
139
140 void Reset() {
141 internal_memset(s: &pc_vector[0], c: 0, n: sizeof(pc_vector[0]) * pc_vector.size());
142 }
143
144 void Dump() {
145 if (!initialized || !common_flags()->coverage) return;
146 __sanitizer_dump_coverage(pcs: pc_vector.data(), len: pc_vector.size());
147 }
148
149 private:
150 bool initialized;
151 InternalMmapVectorNoCtor<uptr> pc_vector;
152};
153
154static TracePcGuardController pc_guard_controller;
155
156// A basic default implementation of callbacks for
157// -fsanitize-coverage=inline-8bit-counters,pc-table.
158// Use TOOL_OPTIONS (UBSAN_OPTIONS, etc) to dump the coverage data:
159// * cov_8bit_counters_out=PATH to dump the 8bit counters.
160// * cov_pcs_out=PATH to dump the pc table.
161//
162// Most users will still need to define their own callbacks for greater
163// flexibility.
164namespace SingletonCounterCoverage {
165
166static char *counters_beg, *counters_end;
167static const uptr *pcs_beg, *pcs_end;
168
169static void DumpCoverage() {
170 const char* file_path = common_flags()->cov_8bit_counters_out;
171 if (file_path && internal_strlen(s: file_path)) {
172 fd_t fd = OpenFile(path: file_path);
173 FileCloser file_closer(fd);
174 uptr size = counters_end - counters_beg;
175 WriteToFile(fd, buff: counters_beg, buff_size: size);
176 if (common_flags()->verbosity)
177 __sanitizer::Printf(format: "cov_8bit_counters_out: written %zd bytes to %s\n",
178 size, file_path);
179 }
180 file_path = common_flags()->cov_pcs_out;
181 if (file_path && internal_strlen(s: file_path)) {
182 fd_t fd = OpenFile(path: file_path);
183 FileCloser file_closer(fd);
184 uptr size = (pcs_end - pcs_beg) * sizeof(uptr);
185 WriteToFile(fd, buff: pcs_beg, buff_size: size);
186 if (common_flags()->verbosity)
187 __sanitizer::Printf(format: "cov_pcs_out: written %zd bytes to %s\n", size,
188 file_path);
189 }
190}
191
192static void Cov8bitCountersInit(char* beg, char* end) {
193 counters_beg = beg;
194 counters_end = end;
195 Atexit(function: DumpCoverage);
196}
197
198static void CovPcsInit(const uptr* beg, const uptr* end) {
199 pcs_beg = beg;
200 pcs_end = end;
201}
202
203} // namespace SingletonCounterCoverage
204
205} // namespace
206} // namespace __sancov
207
208namespace __sanitizer {
209void InitializeCoverage(bool enabled, const char *dir) {
210 static bool coverage_enabled = false;
211 if (coverage_enabled)
212 return; // May happen if two sanitizer enable coverage in the same process.
213 coverage_enabled = enabled;
214 Atexit(function: __sanitizer_cov_dump);
215 AddDieCallback(callback: __sanitizer_cov_dump);
216}
217} // namespace __sanitizer
218
219extern "C" {
220SANITIZER_INTERFACE_ATTRIBUTE void __sanitizer_dump_coverage(const uptr* pcs,
221 uptr len) {
222 return __sancov::SanitizerDumpCoverage(unsorted_pcs: pcs, len);
223}
224
225SANITIZER_INTERFACE_WEAK_DEF(void, __sanitizer_cov_trace_pc_guard, u32* guard) {
226 if (!*guard) return;
227 __sancov::pc_guard_controller.TracePcGuard(
228 guard, pc: StackTrace::GetPreviousInstructionPc(GET_CALLER_PC()));
229}
230
231SANITIZER_INTERFACE_WEAK_DEF(void, __sanitizer_cov_trace_pc_guard_init,
232 u32* start, u32* end) {
233 if (start == end || *start) return;
234 __sancov::pc_guard_controller.InitTracePcGuard(start, end);
235}
236
237SANITIZER_INTERFACE_ATTRIBUTE void __sanitizer_dump_trace_pc_guard_coverage() {
238 __sancov::pc_guard_controller.Dump();
239}
240SANITIZER_INTERFACE_ATTRIBUTE void __sanitizer_cov_dump() {
241 __sanitizer_dump_trace_pc_guard_coverage();
242}
243SANITIZER_INTERFACE_ATTRIBUTE void __sanitizer_cov_reset() {
244 __sancov::pc_guard_controller.Reset();
245}
246// Default implementations (weak).
247// Either empty or very simple.
248// Most users should redefine them.
249SANITIZER_INTERFACE_WEAK_DEF(void, __sanitizer_cov_trace_cmp, void) {}
250SANITIZER_INTERFACE_WEAK_DEF(void, __sanitizer_cov_trace_cmp1, void) {}
251SANITIZER_INTERFACE_WEAK_DEF(void, __sanitizer_cov_trace_cmp2, void) {}
252SANITIZER_INTERFACE_WEAK_DEF(void, __sanitizer_cov_trace_cmp4, void) {}
253SANITIZER_INTERFACE_WEAK_DEF(void, __sanitizer_cov_trace_cmp8, void) {}
254SANITIZER_INTERFACE_WEAK_DEF(void, __sanitizer_cov_trace_const_cmp1, void) {}
255SANITIZER_INTERFACE_WEAK_DEF(void, __sanitizer_cov_trace_const_cmp2, void) {}
256SANITIZER_INTERFACE_WEAK_DEF(void, __sanitizer_cov_trace_const_cmp4, void) {}
257SANITIZER_INTERFACE_WEAK_DEF(void, __sanitizer_cov_trace_const_cmp8, void) {}
258SANITIZER_INTERFACE_WEAK_DEF(void, __sanitizer_cov_trace_switch, void) {}
259SANITIZER_INTERFACE_WEAK_DEF(void, __sanitizer_cov_trace_div4, void) {}
260SANITIZER_INTERFACE_WEAK_DEF(void, __sanitizer_cov_trace_div8, void) {}
261SANITIZER_INTERFACE_WEAK_DEF(void, __sanitizer_cov_trace_gep, void) {}
262SANITIZER_INTERFACE_WEAK_DEF(void, __sanitizer_cov_trace_pc_indir, void) {}
263SANITIZER_INTERFACE_WEAK_DEF(void, __sanitizer_cov_load1, void){}
264SANITIZER_INTERFACE_WEAK_DEF(void, __sanitizer_cov_load2, void){}
265SANITIZER_INTERFACE_WEAK_DEF(void, __sanitizer_cov_load4, void){}
266SANITIZER_INTERFACE_WEAK_DEF(void, __sanitizer_cov_load8, void){}
267SANITIZER_INTERFACE_WEAK_DEF(void, __sanitizer_cov_load16, void){}
268SANITIZER_INTERFACE_WEAK_DEF(void, __sanitizer_cov_store1, void){}
269SANITIZER_INTERFACE_WEAK_DEF(void, __sanitizer_cov_store2, void){}
270SANITIZER_INTERFACE_WEAK_DEF(void, __sanitizer_cov_store4, void){}
271SANITIZER_INTERFACE_WEAK_DEF(void, __sanitizer_cov_store8, void){}
272SANITIZER_INTERFACE_WEAK_DEF(void, __sanitizer_cov_store16, void){}
273SANITIZER_INTERFACE_WEAK_DEF(void, __sanitizer_cov_8bit_counters_init,
274 char* start, char* end) {
275 __sancov::SingletonCounterCoverage::Cov8bitCountersInit(beg: start, end);
276}
277SANITIZER_INTERFACE_WEAK_DEF(void, __sanitizer_cov_bool_flag_init, void) {}
278SANITIZER_INTERFACE_WEAK_DEF(void, __sanitizer_cov_pcs_init, const uptr* beg,
279 const uptr* end) {
280 __sancov::SingletonCounterCoverage::CovPcsInit(beg, end);
281}
282} // extern "C"
283// Weak definition for code instrumented with -fsanitize-coverage=stack-depth
284// and later linked with code containing a strong definition.
285// E.g., -fsanitize=fuzzer-no-link
286// FIXME: Update Apple deployment target so that thread_local is always
287// supported, and remove the #if.
288// FIXME: Figure out how this should work on Windows, exported thread_local
289// symbols are not supported:
290// "data with thread storage duration may not have dll interface"
291#if !SANITIZER_APPLE && !SANITIZER_WINDOWS
292SANITIZER_INTERFACE_ATTRIBUTE SANITIZER_WEAK_ATTRIBUTE
293thread_local uptr __sancov_lowest_stack;
294#endif
295
296#endif // !SANITIZER_FUCHSIA
297